You are on page 1of 2

ISO 27001 RISK ASSESSMENT TEMPLATE

COMPANY NAME
TAFASEEL

ISO 27001 RISK RATING


ASSET REFERENCE
CONTROL CONTROL ASSET CONFIDENTIAL? RISK DETAILS (1 - LOWEST, COMPLETE?
NUMBER
REFERENCE 10 - HIGHEST)

Information Security Policies 5 10

Management direction for


5.1
information security

Organization of information security 6

Information security roles and responsibilities 6.1.1

Human resources security 7

Terms and conditions of employment 7.1.2

Asset management 8

Responsibilities for assets 8.1.2

Access control 9

Responsibilities for assets 9.2.6

Cryptography 10

Secure areas 11

Physical security perimeter 11.1.1

Operations Security 12

Communications security 13

System acquisition, development and


14
maintenance

Suppliers relationships 15

Information security incident management 16

Information security aspects of business


17
continuity management

Compliance 18
Privacy and protection of personally
18.1.4
identifiable information

You might also like